Legal
Privacy Policy
What we collect, what we refuse to collect, and exactly how to get rid of all of it.
- 12 September 2026
- All Figo apps and figoapp.net
The short version
In one paragraph
The rest of this page is the long version. It is written to be read, not to be survived.
Who we are
Figo is a software studio operated by Varun Anand, an individual developer based in India. Figo publishes Recurrs and is building Neuron.
This policy governs the Figo apps, this website, and any related services. Using them means you accept it. Where a specific app does something different, that difference is called out by name below.
What we collect
Information you give us
| Data | When | Where it lives |
|---|---|---|
| Name and email address | When you create an account | Supabase, encrypted at rest |
| Subscriptions, expenses, income, trials, loans | When you add them | On device, and in Supabase for sync |
| Payment methods and balances | When you add them | On device and Supabase — names and balances only, never card numbers |
| Receipts and attachments | When you scan or upload | Supabase storage |
| Profiles and connections | When you create or accept them | Supabase |
| Support messages and feedback | When you send them | Supabase |
Information collected automatically
- Device and OS version — for compatibility and crash diagnostics.
- Push token — stored only so renewal notifications can be delivered. Never used for tracking.
- App version — sent with API requests so the server knows what it is talking to.
- Exchange rates — fetched from a public rates API. No personal data is sent with that request.
What we never collect
- Card numbers, CVVs, or bank account details.
- Bank logins or real transaction feeds. Figo apps do not connect to your bank at all.
- Background location. Location automations run against a radius you set, evaluated on your device.
- Your contact list or calendar.
- Photos, beyond the specific images you choose to attach.
- Email message bodies. See Gmail scanning.
- Browsing history, or data from any other app on your device.
How we use it
Strictly to run the service. There is no advertising business here to feed.
| Purpose | Data used | Basis |
|---|---|---|
| Running the tracking features | Your entries | Contract |
| Sync across your devices | Your entries, account ID | Contract |
| Renewal reminders | Dates, push token | Contract |
| AI insights and autofill | Names, amounts, categories | Consent — opt-in |
| Gmail subscription detection | Sender and subject lines | Consent — opt-in |
| Verifying a paid subscription | Account ID, store receipt | Contract |
| Preventing abuse of AI quotas | Account ID, usage counts | Legitimate interest |
Gmail scanning
Entirely optional
What is read
- Sender addresses and subject lines only. Message bodies are never downloaded or read.
- The query is filtered to billing language — receipt, invoice, subscription — to keep the scope narrow.
- Only the last six months of mail is considered.
What is stored
- A Google refresh token, held server-side in Supabase, encrypted at rest and fenced by row-level security. It never reaches your device and is never returned in an API response.
- The derived result only — for example “Spotify, ₹119 monthly”. The email addresses and subjects that produced it are not stored anywhere.
Google’s rules
Our use of data from Gmail follows the Google API Services User Data Policy, including its Limited Use requirements. Gmail data is never used for advertising, never sold or passed to a third party for their own use, and never used to train any AI model.
Disconnecting deletes the refresh token immediately and clears cached suggestions. Subscriptions you already added stay — removing them is your call.
AI features
AI autofill and the AI analyser run through our own backend, which calls Google’s Gemini API. The request carries the figures it needs and nothing that identifies you.
- Sent: subscription and expense names, amounts, billing cycles, categories, and aggregate totals.
- Never sent: your name, email, account ID, device details, or anything from your inbox.
Not financial advice
Storage and security
On your device
Entries are stored locally so the app works offline, using each platform’s native store.
In the cloud
Sync and accounts run on Supabase, a managed PostgreSQL platform hosted on AWS. Everything there is:
- encrypted in transit over TLS 1.2 or higher;
- encrypted at rest with AES-256;
- fenced by row-level security — database-level policies that make one account’s rows unreadable to another, even if the application layer were compromised.
Keys
The public key embedded in our apps and in this website is designed to be public. It grants nothing on its own: every read and write is still checked against row-level security, and personal data requires a valid signed-in session.
What we cannot promise
Third parties
| Service | Purpose | What it sees |
|---|---|---|
| Supabase | Database, auth, storage, edge functions | Account details and your entries |
| Google Gemini | AI autofill and analysis | Figures and category names, no identity |
| Google OAuth / Gmail | Optional billing-email detection | Sender addresses and subjects, processed and discarded |
| Apple | App Store payments, push delivery | Payment data — Apple only, never us |
| Google Play | Android payments | Payment data — Google only, never us |
| Public rates API | Currency conversion | Nothing personal |
There are no advertising networks, tracking SDKs or analytics frameworks inside the apps.
Sign-in and passwords
- Email and password — hashed with bcrypt by Supabase Auth before storage. We never see or store a plaintext password.
- Sign in with Apple — we receive a name and an email or relay address. Never your Apple ID password.
- Sign in with Google — we receive a name and email address. Never your Google password.
Sessions use short-lived JSON Web Tokens held in the app’s sandboxed storage, and all auth traffic is HTTPS.
Payments
Every purchase is processed by Apple or Google as merchant of record. We never receive, process or store card numbers or bank details. What reaches us is a receipt confirming whether a paid subscription is currently active — nothing more.
Retention and deletion
- While your account is active, we keep your data so the apps work.
- On account deletion, everything personal is permanently removed from our database within 30 days. Deleting the app removes the on-device copy immediately.
- Gmail refresh tokens are deleted the moment you disconnect, or on account deletion.
- Push tokens are deleted on account deletion or when you revoke notifications.
- Disaster-recovery backups roll off within seven days and are not individually restorable.
- Free-tier receipts are purged after seven days by design; receipts captured while subscribed are kept.
Delete your account from inside the app under Settings, or ask us and we will do it.
Your rights
| Right | What it means | How |
|---|---|---|
| Access | A copy of what we hold about you | Ask us |
| Rectification | Correct anything wrong | Edit in the app |
| Erasure | Delete the account and everything with it | Settings → Account → Delete |
| Portability | Machine-readable export | Export to CSV / Excel |
| Restriction | Limit how we process your data | Ask us |
| Objection | Object to legitimate-interest processing | Ask us |
| Withdraw consent | Turn off Gmail scanning or AI | App settings, any time |
We answer verifiable requests within 30 days. If you are in the EEA, UK or California you have additional rights under GDPR, UK GDPR or CCPA — we apply them to everyone regardless of where you live.
Children
Figo apps are not directed at children under 13, or under 16 in the EEA, and we do not knowingly collect their data. If you believe a child has given us personal information, tell us and we will delete it promptly.
International users
Figo operates from India; our infrastructure runs in the United States. Using the service means your data may be transferred to and processed in both. For EEA and UK users we rely on consent for optional features and on contract performance for the rest, and our infrastructure provider operates under the EU-US Data Privacy Framework.
This website
figoapp.net sets no advertising or tracking cookies and runs no third-party analytics. The forms on the feedback, contact and testers pages submit directly to our own database and store only what you typed, plus your browser’s user-agent string, which helps us reproduce bugs.
Changes
We update this policy when practice, technology or law changes. Material changes get a notice in-app and a new effective date at the top of this page. Continuing to use the apps after that means you accept the revision.
Contact
Privacy questions go to figo.productive@gmail.com, or through the contact form. Read the Terms of Service alongside this policy — they work together.